Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Brief
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution.
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, . NET, and a range of other components. Sixty-two are rated Critical. One is already being exploited in the wild.
The good news, such as it is, is that the ratio of bugs being reported to bugs being actively exploited hasn’t moved — there’s no equivalent surge in zero-day exploitation to match the volume of fixes.
The actively exploited bug is CVE-2026-68820 , a use-after-free flaw in afd. sys, the kernel-mode driver that underpins the Windows Sockets API.
